SkyFuse Privacy Policy
1. Who operates SkyFuse
SkyFuse (skyfuse.net) is operated by its individual owner, reachable at support@skyfuse.net. That address handles all privacy requests.
2. Scope
This policy covers skyfuse.net. It does not cover Discord, Hypixel, or other third-party services you use alongside SkyFuse.
3. Data collected when you sign in with Discord
- Discord user ID;
- Discord username;
- Discord global display name, when set;
- Discord avatar reference (hash), when set;
- account timestamps (created, updated, last sign-in) and the accepted legal-document versions.
4. Authentication and session data
- opaque server-side session records (a keyed hash of the session token, creation/expiry/last-seen timestamps);
- one essential authentication cookie (
sf_session) and, during sign-in only, a short-lived state cookie (sf_oauth_state).
5. Security and hosting data
SkyFuse runs on Cloudflare. Cloudflare processes connection data (such as IP addresses) transiently to serve and protect the site, and provides us aggregated analytics and short-lived operational logs. SkyFuse’s own database does not store your IP address.
6. Data we do not collect for login
- no password (there is none);
- no Discord email address;
- no Discord server (guild) list;
- no Discord messages;
- no Discord connections.
Discord is the only way to sign in to SkyFuse. There is no Microsoft, Xbox or Minecraft account connection, and SkyFuse requests no Discord permissions beyond the identify scope described above. Where a SkyFuse tool asks you to type a Minecraft username, that name is used only to look up public Hypixel data for that request — it is not a verified account link and it is not stored on your account.
6a. Community data
If you use the community features, SkyFuse also stores, linked to your account: your SkyCoins balance and lifetime totals, your daily streak counters and reward-claim periods, which cosmetics you own and have equipped, your SkyCoin transaction ledger, your purchases, and your “reduce animations” preference. This data is generated by your own use of SkyFuse — none of it comes from Discord.
Your username, avatar, profile statistics and equipped cosmetics are visible to other signed-in SkyFuse members on your profile and on the leaderboards. Your transaction ledger, reward-claim history and purchase history are private and visible only to you. Anonymous visitors cannot see member profiles or leaderboards at all.
6b. Saved site preferences
SkyFuse stores your display settings against your account so that the site looks and behaves the same on every device you sign in on. These are:
- your selected site theme;
- navigation density and whether sidebar descriptions are shown;
- your motion setting (system, full, or reduced);
- 12-hour or 24-hour time format;
- your timezone choice — browser, UTC, or a timezone you pick;
- which view the Calendar & Events page opens on;
- whether collapsed navigation sections are remembered.
These are settings you choose. They contain no personal information, they are never shared with another member or a third party, and they are deleted with the rest of your data when you delete your account. A copy is also kept in your browser’s local storage so the right theme is applied before the page first paints; clearing your browser storage removes that copy, and your saved settings return the next time you sign in.
7. Purposes
We process this data to provide the account you requested, keep you signed in, protect the service against abuse, and honor your legal rights.
8. Legal bases
- performance of the requested service (account, sessions);
- legitimate interest in security and abuse prevention;
- consent, only where we would actually ask for it (none of the current processing relies on consent beyond your sign-in action).
9. Sources
Data comes from you, from Discord’s OAuth interface when you authorize sign-in, and from public Hypixel endpoints for game-market content (which contains no SkyFuse-account data).
10. Recipients
Discord (during sign-in) and Cloudflare (hosting and storage) are the only service providers involved. We do not sell or share your personal data with anyone else.
11. International transfers
Cloudflare and Discord are international providers; data may be processed outside your country under their respective safeguards (such as EU standard contractual clauses, as described in their own data-protection documentation).
12. Retention
- sessions: up to 30 days, or until sign-out/revocation;
- account profile and community data (balance, streaks, ownership, ledger, purchases): until you delete the account or it is no longer necessary;
- saved site preferences (theme, navigation, motion, time format, timezone, calendar view): until you change them or delete the account;
- OAuth sign-in state: minutes (10-minute expiry, then removed);
- temporary Discord access token: never stored — used once for the profile fetch and discarded;
- security events: SkyFuse does not currently keep its own security-event log.
13. Account deletion
You can delete your account on the account page at any time; this revokes all sessions and permanently removes your profile data, community data and saved site preferences. You can also request deletion by email.
14. Your rights (GDPR)
You have the rights to information, access, correction, deletion, restriction, portability, and objection where applicable, to withdraw consent where consent is used, and to complain to your supervisory authority (in Romania: ANSPDCP).
15. Submitting a privacy request
Email support@skyfuse.net from an address that lets us verify your request. Account deletion is also available directly on the account page.
16. Children
SkyFuse accounts require Discord eligibility; SkyFuse is not directed at children below the age at which they can validly use Discord in their country.
17. Cookies
SkyFuse sets only strictly necessary cookies: the authentication session cookie and the short-lived sign-in state cookie. There are no advertising or third-party tracking cookies, so no cookie consent banner is required.
18. No sale of personal data
We do not sell personal data.
19. No advertising use
We do not use your personal data for advertising. If that ever changes, this policy will be updated first.
20. Security
Sessions use HttpOnly, Secure cookies; tokens are stored only as keyed hashes; OAuth exchanges happen server-side; secrets are held in encrypted platform storage. No internet service can promise perfect security.
21. Changes to this policy
Material changes will be reflected by a new “Last updated” date and, where required, a fresh acceptance prompt.